Home Rogue Websites Desktopsecuritylab.com

Desktopsecuritylab.com

Posted: August 18, 2010

Desktopsecuritylab.com is a rogue domain that promotes the Desktop Security 2010 rogue anti-spyware program. Desktopsecuritylab.com advertises this fake program that supposedly fights against the attacks of viruses, spyware, hijackers, worms, Trojans, keyloggers and other malicious infections. Stay clear of this rogue anti-spyware program and the Desktopsecuritylab.com website that distributes it. Get rid of Desktopsecuritylab.com using a reliable anti-spyware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Desktop Security 2010.lnk
    2 %UserProfile%\Local Settings\Temp\gedx_ae09.exe
    3 %UserProfile%\Local Settings\Temp\jkfuckjs.exe
    4 %UserProfile%\Local Settings\Temp\kgn.exe
    5 %UserProfile%\Local Settings\Temp\kilslmd.exe
    6 %UserProfile%\Local Settings\Temp\kn.a.exe
    7 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Security 2010
    8 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Security 2010.lnk
    9 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Security 2010\Activate Desktop Security 2010.lnk
    10 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Security 2010\Desktop Security 2010.lnk
    11 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Security 2010\Help Desktop Security 2010.lnk
    12 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Security 2010\How to Activate Desktop Security 2010.lnk
    13 c:\Program Files\Desktop Security 2010
    14 c:\Program Files\Desktop Security 2010\daily.cvd
    15 c:\Program Files\Desktop Security 2010\Desktop Security 2010.exe
    16 c:\Program Files\Desktop Security 2010\guide.chm
    17 c:\Program Files\Desktop Security 2010\hjengine.dll
    18 c:\Program Files\Desktop Security 2010\mfc71.dll
    19 c:\Program Files\Desktop Security 2010\MFC71ENU.DLL
    20 c:\Program Files\Desktop Security 2010\msvcp71.dll
    21 c:\Program Files\Desktop Security 2010\msvcr71.dll
    22 c:\Program Files\Desktop Security 2010\pthreadVC2.dll
    23 c:\Program Files\Desktop Security 2010\securitycenter.exe
    24 c:\Program Files\Desktop Security 2010\taskmgr.dll
    25 c:\Program Files\Desktop Security 2010\uninstall.exe
    26 c:\WINDOWS\system32\[random characters].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "C:\Program Files\Desktop Security 2010\Desktop Security 2010.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Desktop Security 2010HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform "Desktop Security 2010"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Desktop Security 2010"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SecurityCenter"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random characters]"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Desktop Security 2010
Loading...